Configure Codex model, reasoning and access permissions
Model choice and file access are separate controls. The account owner can select a compatible model and reasoning level, then decide whether the task is read-only, may write to the workspace or may use full access.
Start with read-only execution
Read-only access is the safest default for exploring a repository, reviewing tests or asking for a plan. It lets Codex inspect the project without changing files.
Authorize workspace writes or full access
Workspace-write access permits changes inside the configured project. Full access is an explicit account-level choice and should be enabled only when the owner accepts the broader operating scope.
Handle approval requests
When an operation needs confirmation, the pending request is surfaced in the task conversation and reminded periodically. Approve or decline it from the authorized owner account; do not treat a waiting state as a failed task.
Connect your first VM
Start with 2,000 messages and test the workflow from your own environment.